Arsenal public
Exploits
868 CVE indexées ont un exploit public prêt à l'emploi, dont 108 au KEV CISA et 326 touchant une app suivie.
- CVE avec exploit
- 868
- Exploits recensés
- 1 031
- Au KEV CISA
- 108
- Sur le parc suivi
- 326
| CVE | Sévérité | Sources | EPSS | Apps |
|---|---|---|---|---|
|
CVE-2019-0708
KEV
Remote Desktop Services Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2021-44228
KEV
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuratio… |
CRITICAL | ExploitDB Nuclei | 100% | |
|
CVE-2025-53770
KEV
Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over… |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2021-26855
KEV
Microsoft Exchange Server Remote Code Execution Vulnerability |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2024-4577
KEV
Argument Injection in PHP-CGI |
CRITICAL | ExploitDB Nuclei | 100% | — |
|
CVE-2017-0199
KEV
Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2019-0604
KEV
Microsoft SharePoint Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 100% | — |
|
CVE-2014-0497
KEV
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, a… |
CRITICAL | ExploitDB | 100% | |
|
CVE-2020-0796
KEV
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles ce… |
CRITICAL | ExploitDB Nuclei | 100% | |
|
CVE-2020-1472
KEV
Netlogon Elevation of Privilege Vulnerability |
CRITICAL | ExploitDB | 99% | |
|
CVE-2017-0148
KEV
Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 99% | |
|
CVE-2020-0646
KEV
.NET Framework Remote Code Execution Injection Vulnerability |
CRITICAL | ExploitDB | 99% | — |
|
CVE-2020-1147
KEV
.NET Framework, SharePoint Server, and Visual Studio Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 94% | — |
|
CVE-2017-0143
KEV
Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 93% | |
|
CVE-2017-8464
KEV
LNK Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 90% | |
|
CVE-2017-0146
KEV
Windows SMB Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 90% | |
|
CVE-2020-0674
KEV
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 87% | — |
|
CVE-2016-5195
KEV
Indexed via Android Security Bulletin — full NVD metadata pending. |
CRITICAL | ExploitDB | 84% | |
|
CVE-2010-3765
KEV
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMon… |
CRITICAL | ExploitDB | 83% | |
|
CVE-2019-1429
KEV
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 77% | — |
|
CVE-2018-8298
KEV
Scripting Engine Memory Corruption Vulnerability |
CRITICAL | ExploitDB | 75% | — |
|
CVE-2017-8540
KEV
Microsoft Malware Protection Engine Remote Code Execution Vulnerability |
CRITICAL | ExploitDB | 72% | — |
|
CVE-2025-32463
KEV
Sudo before 1.9.17p1 allows local users to obtain root access |
CRITICAL | ExploitDB | 61% | — |
|
CVE-2019-11708
KEV
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the n… |
CRITICAL | ExploitDB | 56% | |
|
CVE-2025-24085
KEV
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.… |
CRITICAL | ExploitDB | 18% | |
|
CVE-2023-44487
KEV
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams … |
HIGH | ExploitDB | 100% | |
|
CVE-2021-41773
KEV
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49 |
HIGH | ExploitDB Nuclei | 100% | — |
|
CVE-2020-0688
KEV
Microsoft Exchange Validation Key Remote Code Execution Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-11882
KEV
Microsoft Office Memory Corruption Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2021-27065
KEV
Microsoft Exchange Server Remote Code Execution Vulnerability |
HIGH | ExploitDB | 100% | — |
|
CVE-2017-0147
KEV
Windows SMB Information Disclosure Vulnerability |
HIGH | ExploitDB | 100% | |
|
CVE-2017-0144
KEV
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 99% | |
|
CVE-2020-0618
KEV
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests… |
HIGH | ExploitDB Nuclei | 99% | — |
|
CVE-2018-20250
KEV
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE… |
HIGH | ExploitDB | 96% | |
|
CVE-2021-4034
KEV
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed… |
HIGH | ExploitDB | 95% | — |
|
CVE-2016-0189
KEV
The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products,… |
HIGH | ExploitDB | 94% | — |
|
CVE-2017-8570
KEV
Microsoft Office Remote Code Execution Vulnerability |
HIGH | ExploitDB | 90% | — |
|
CVE-2017-0145
KEV
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2… |
HIGH | ExploitDB | 90% | |
|
CVE-2022-0847
KEV
Indexed via Android Security Bulletin — full NVD metadata pending. |
HIGH | ExploitDB | 90% | |
|
CVE-2020-0601
KEV
Windows CryptoAPI Spoofing Vulnerability |
HIGH | ExploitDB | 89% | |
|
CVE-2017-8759
KEV
.NET Framework Remote Code Execution Vulnerability |
HIGH | ExploitDB | 89% | — |
|
CVE-2018-8174
KEV
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript… |
HIGH | ExploitDB | 88% | |
|
CVE-2016-9079
KEV
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered i… |
HIGH | ExploitDB | 87% | |
|
CVE-2009-3459
KEV
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows remote attac… |
HIGH | ExploitDB | 87% | |
|
CVE-2017-0213
KEV
Windows COM Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 84% | |
|
CVE-2016-7200
KEV
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of s… |
HIGH | ExploitDB | 83% | |
|
CVE-2025-33073
KEV
Windows SMB Client Elevation of Privilege Vulnerability |
HIGH | ExploitDB | 83% | |
|
CVE-2019-0752
KEV
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer,… |
HIGH | ExploitDB | 82% | — |
|
CVE-2023-4911
KEV
Microsoft Security Update Guide entry — NVD enrichira. |
HIGH | ExploitDB | 81% | — |
|
CVE-2016-7255
KEV
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S… |
HIGH | ExploitDB | 81% |
Exploits agrégés depuis ExploitDB, Nuclei, Metasploit et les PoC GitHub, mappés aux CVE que Scout indexe. À des fins de recherche défensive et de test d'exposition uniquement.